Enterprise Risk & Internal Controls
Where the business can fail, whether the control that should catch it works, and what to fix first.
Risk & controls
Governance frameworks, board and committee structure, delegation of authority and the reporting a board needs to oversee management credibly.
Usually at one of three moments: an outside investor joins the board and asks questions nobody has documented answers to, a fraud loss reveals that one person could both initiate and approve the same payment, or an acquirer's diligence team asks for a delegation of authority matrix that does not exist. The work is board and committee structure, delegation of authority, and reporting a board can genuinely oversee management with.
Corporate governance advisory in California is not paperwork, and it is not a compliance exercise borrowed from public companies. It is the set of arrangements that let a board know whether management's account of the business is true, and let management act decisively without the board discovering things after the fact.
For a private company that has never needed any of it, the practical test is not whether the arrangements look impressive in a binder. It is whether a director can establish, without asking management to confirm it, that the controls they are relying on exist and are working.
Stripped of the language, five things:
Most private companies have some of this informally. The value of writing it down is not bureaucratic; it is that informal arrangements fail exactly when they are needed, which is when the person who held them in their head is the subject of the question.
Plenty of companies in Ventura County and Los Angeles County are owner-managed with a nominal board that meets once a year to sign resolutions. Governance advisory is still relevant, but the framing changes from board oversight to operating discipline.
The questions become concrete. Who can change a supplier's bank details, and does anyone verify the change by a channel other than the email that requested it. Who reviews the bank reconciliation, and is it the same person who prepares it. What happens if the founder is unreachable for three weeks. Who has administrative access to the accounting system, and when was that list last examined.
These sound operational because they are. They are also, in aggregate, the governance framework of a company that does not think it has one, and each of them corresponds to a loss that a comparable company somewhere has already suffered.
Audit committees in mid-market companies are frequently composed of directors with real commercial experience and no assurance background. They are asked to evaluate the external auditor, form a view on management's judgments, oversee the internal control environment, and respond to whistleblower reports, without a technical adviser of their own.
Support here typically covers charter drafting, an annual work plan mapped to the reporting calendar, preparation for the auditor's required communications and what the committee should probe in them, independent review of significant accounting judgments, and briefing on matters where the committee's obligations differ from management's.
Having spent twenty years on the auditor's side of that table informs what is actually useful: the questions that reliably surface a problem, and the answers that sound reassuring but are not.
Boards are increasingly expected to oversee cybersecurity and, now, AI adoption, usually without anyone in the room who can evaluate what they are being told. The result is a briefing that either alarms without informing or reassures without evidence.
Practical oversight is narrower than the topic suggests. For cybersecurity: what would a material incident actually cost this company, which third parties hold our data, what is the actual recovery time rather than the target, and when was that last tested. For AI: where is it in use, what data goes into it, who validated the output before it was relied upon, and what is the position if a customer asks whether their data trained a model.
Because this practice also performs the underlying cybersecurity risk assessment work, the board briefing is grounded in what the assessment found rather than in generic risk language.
Governance advisory and assurance cannot be performed by the same party on the same subject matter. An advisor who designs a control framework cannot then provide an objective opinion on whether it works, and any firm offering both on the same engagement is offering you a compromised outcome.
Both services exist here, and the boundary is agreed in writing at the start. Where this practice designs, the testing goes elsewhere. Where this practice tests (see internal controls assessment) the design work belongs to management or another advisor.
Interviews with directors and senior management, review of existing charters, minutes, policies and authority limits. What exists on paper is compared with what actually happens.
A framework proportionate to the company, decision rights, committee structure, reporting cadence and escalation routes. Proportionality is the point; public-company machinery in a $20M business fails from disuse.
Documents drafted, system permissions aligned to the authority matrix, reporting templates built, and the people who will operate the process trained in it.
A first cycle observed, then an annual review. Frameworks decay when roles change, and the review is what catches the drift.
This service is delivered on site and remotely across the firm's service area. See how it applies locally:
Not answered here? Ask Javed directly
An advisor designs and recommends the arrangements through which a company is directed and controlled, decision rights, board and committee structure, reporting lines, risk appetite, and the escalation routes that carry bad news upward. The advisor does not run the company and does not independently assure that the arrangements work.
That second function belongs to internal audit, which tests whether the design operates as intended and reports to the board rather than to management. The separation exists for a reason: no one objectively audits a structure they built themselves. Ultimate responsibility for governance remains with the board either way.
Frequently more relevant than to a widely-held company, because family businesses carry a specific structural risk: the informal arrangements that work while everyone is in agreement have no defined behaviour when someone is not.
The pressure points are familiar, a second generation entering the business, a family member employed in a role they would not have been recruited into, transactions between the company and family entities, and succession that has been discussed but never documented. These are governance questions with unusually high emotional cost, and they are far cheaper to address in advance of the event that forces them.
Not unless a regulator, a lender or an investor agreement requires one. What most mid-market private companies benefit from is smaller: at least one director without an executive role who reviews the financial reporting, has an independent relationship with the external auditor, and can ask management a question without it being a confrontation.
Standing up a full committee with a charter, a work plan and quarterly meetings for a company with a five-person board is usually theatre. It consumes time and produces documents nobody reads.
The determining factor is whether the process was designed before the report arrived. If the only route for a concern runs through the executive it concerns, the company will not hear about it, and when it does, the response will be improvised under pressure and will likely make the situation worse.
A workable process needs a reporting channel outside the management line, a defined non-executive recipient, a documented triage step, and a pre-agreed position on when outside investigators are engaged. This is an hour of design work that pays for itself once.
A framework assessment and design engagement for a single-entity mid-market company generally runs four to six weeks. The variables are entity count, whether a functioning board already exists, and how much documentation is in place.
Board education sessions and audit committee support are usually retained separately on an annual basis tied to the meeting calendar, which is a considerably smaller commitment than the initial design work.
Where the business can fail, whether the control that should catch it works, and what to fix first.
Risk & controlsAccess, change and operations controls tested by someone who can read both an access listing and a general ledger.
IT audit & ITGCQuality of earnings, working capital, and the IT and privacy exposure that now decides deal terms as often as the numbers do.
Deal advisoryThree decades of audit, controls and finance leadership across banking, card, mortgage, insurance, staffing and semiconductor.
Get in touch
A sentence or two about your situation (the standard involved, the deadline, and what has already been attempted) is enough to get a useful reply.
Send the shape of it. The first call is diagnostic, not billed, and it regularly ends with a smaller engagement than the one you asked about.
Thirty years of audit, financial leadership and IT governance in one engagement, and a direct answer about scope, sequence and cost before anything is signed.
Or speak to Javed directly (310) 980-3958 Message on WhatsApp